Files
windows-itpro-docs/windows/security/threat-protection/auditing/audit-directory-service-replication.md
Docs Allowlist Management 8cd92d66ee In all content, remove
ms.technology = itpro-security paired with ms.prod = windows-client

Replace with

ms.subservice = itpro-security paired with ms.service=windows-client
2024-01-12 19:42:18 +00:00

2.5 KiB
Raw Blame History

title, description, ms.assetid, ms.reviewer, manager, ms.author, ms.pagetype, ms.mktglfcycl, ms.sitesec, ms.localizationpriority, author, ms.date, ms.topic
title description ms.assetid ms.reviewer manager ms.author ms.pagetype ms.mktglfcycl ms.sitesec ms.localizationpriority author ms.date ms.topic
Audit Directory Service Replication Audit Directory Service Replication is a policy setting that decides if audit events are created when replication between two domain controllers begins or ends. b95d296c-7993-4e8d-8064-a8bbe284bd56 aaroncz vinpa security deploy library low vinaypamnani-msft 09/06/2021 reference

Audit Directory Service Replication

Audit Directory Service Replication determines whether the operating system generates audit events when replication between two domain controllers begins and ends.

Event volume: Medium on domain controllers.

Computer Type General Success General Failure Stronger Success Stronger Failure Comments
Domain Controller No No IF IF IF - Events in this subcategory typically have an informational purpose and it is difficult to detect any malicious activity using these events. Its mainly used for Active Directory replication troubleshooting.
Member Server No No No No This subcategory makes sense only on domain controllers.
Workstation No No No No This subcategory makes sense only on domain controllers.

Events List:

  • 4932(S): Synchronization of a replica of an Active Directory naming context has begun.

  • 4933(S, F): Synchronization of a replica of an Active Directory naming context has ended.